Security

Trusted Sites Actually Deliver Phishing Attacks: Here’s How

While it may seem that trusted sites with domain names you recognize are likely safe, they’re not always what they appear to be. Hackers have discovered a vulnerability in websites that seem secure, yet what they really do is push phishing scams your way.

The best way to protect from such an attack is using an all-purpose online safety app such as  dfndr security, which is packed with antivirus and anti-phishing detection to guard your Android phone against hacker threats.

Read More: 5 Phishing Clues to Look for in Emails from Your Contacts

The more you know how these phishing scams are perpetrated, the better prepared you’ll be for a potential attack. Here’s what you should know.

More Than ⅓ of Trusted Sites May Be Vulnerable
A recent study discovered that out of the top 100,000 sites based on Alexa’s rankings, 42% may be at risk of being hacked. The software used for these sites are not always fully secure, paving the way for hackers to take advantage. The study also found 80,000 phishing sites in 2017, 80,000 of which are reportedly secure.

The vulnerabilities may appear on all sorts of websites, but the most popular targets are business sites, as well as adult and pornography domain names. Other websites that may be compromised include uncategorized sites, parked sites, shopping outlets, gambling hotspots, news, and media domain names, as well as personal blogs.

The Character Conversion Vulnerability
One sign of security that we all know about is websites that use the https:// prefix, along with the little green padlock that touts a website as being secure. However, hackers are able to exploit a vulnerability that can make a fraudulent site mimic the exact appearance of a real website, especially when it comes to websites that don’t use the Latin alphabet.

Common targets are domain names that use Chinese characters or Cyrillic. English-based browsers have to convert these characters into English using Punycode, which translates them. It’s through this conversion process that cybercriminals thrive and “break-in” within this process.

Internet users believe that they are opening a familiar domain name, even though they are taken to a different URL and web server. Following this process, phishing scams are pushed take over by asking you for personal information that can later be used for criminal purposes.

How to Avoid These
Always be cautious of any website that asks for personal information and always update your browser regularly since updates usually fix vulnerabilities and bugs. Take a close look at the link address for extra words that seem out of place for a trusted site and scan any information once the site has loaded for anything out of the ordinary.

Ultimately, the best way to avoid falling prey to a phishing scam that appears to be legitimate is by getting a security app that flags these threats for you.

PSafe Newsroom

The dfndr blog is an informative channel that presents exclusive content on security and privacy in the mobile and business world, with tips to keep users protected. Populated by a select group of expert reporters, the channel has a partnership with dfndr lab's security team. Together they bring you, first-notice news about attacks, scams, internet vulnerabilities, malware and everything affecting cybersecurity.

Recent Posts

24 Billion Passwords Exposed? How to Check If You’re Affected.

A massive password leak has triggered a global security alert: Cybernews researchers identified an exposed…

57 years ago

That QR Code on Your Bar Table During the Game: Would You Scan It Without Thinking?

A QR code on a bar table could hide a phishing link. Learn how to…

57 years ago

Could You Spot a Fake Login Page in 5 Seconds? Take the Phishing Test

Before you keep reading, imagine this: You receive a message warning that your account is…

57 years ago

Is Mobile Data Always Safer Than Public Wi-Fi? Myth or Fact?

You’re at an airport and need to open your banking app. Which would you choose:…

57 years ago

Jury Duty Scam: Fake Arrest Warrants Are Targeting Americans

What would you do if someone claiming to be a U.S. Marshal called and said…

57 years ago

World Cup 2026 Streams: How to Tell Safe Links from Dangerous Ones

Kickoff is minutes away. You search for a 2026 World Cup stream and receive a…

57 years ago